[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: Apple 2 ebay 3rd party checkout, security risk?
"Paul Schlyter" <pausch@saaf.se> wrote in message
news:f2bms0$16pv$1@merope.saaf.se...
> In article <1179201989.388738.209720@n59g2000hsh.googlegroups.com>,
> John <zzzjoki@yahoo.com> wrote:
>
>>> If you are truly paranoid about your DNS setting getting hacked then
>>> you should get off the internet NOW because you are at a much higher
>>> risk of picking up a virus that targets eBay users by simply browsing
>>> a listing than you are by going through icensed eBay partner's checkout
>>> site.
>>
>> How could that be done? Could they embed malicious Javascript code, or
>> something, into an ebay listing page?
>
> There are lots of things they could do indeed....
>
>
> Otoh there's an easy way to avoid this: DO NOT USE AN ACCOUNT WITH
> ADMINISTRATOR'S RIGHTS UNESS YOU REALLY HAVE TO (e.g. when installing
> new software). And particularly when you're surfing the Web, you
> should *not*, repeat, *not* do that from an account with administrator's
> rights!
>
> That simple rule is obeyed quite well in the Unix world, but it's being
> violated so many times, over and over and over and over again, in the
> Windows world, for two reasons: ignorance and laziness. But those who
> do it due to laziness are really shooting themselves in the foot:
> having to reformat your harddrive and reinstall all your apps twice
> a year or so is a lot of work!
>
> Changing your DNS settings requires administrator's rights in the
> account you're logged into and running your web browser from.
> Modifying system files requires administrator's rights too. If you
> instead log on to an account with more limited User's rights, and if
> you should visit a web page containing malicious code trying to do
> nasty things, the OS will prevent it from doing that. But if you're
> logged on to an account with administrator's rights when that happen,
> the OS will "say" to the malicious code: "So you want to change the
> DNS settings? And modify this critical system file? Fine with me -
> you're an administrator, so go right ahead!" -- and then that
> malicious code you loaded into your computer is allowed to perform its
> evil deed.
>
> You're locking the front door to your house, don't you? You don't allow
> anyone to enter your house and just *hope* they won't do anything nasty,
> right? Likewise, you should lock up your computer a bit more, and not
> allow any unknown code to run with administrator's rights!!! Right?
>
> If you do this, you can continue surfing the Web without being worried
> about malicious code changing your DNS settings, or infecting critical
> system files. Wouldn't that be nice?
I agree. I can't imagine how many people are using Windows XP always
have administrator rights while they use their own username. They may
recognize many small software like ActiveX or JavaScript are downloaded
through IE without their knowledge. Restriction Access can prevent it.
Bryan Parkoff